Mykyta Kim, Key2Law, on post-MiCA compliance: ‘A licence alone will no longer be enough to stand out’

In an interview with European Gaming, Mykyta Kim, chief executive officer of Key2Law, explains what the close of the Markets in Crypto-Assets Regulation (MiCA) transitional period on 1 July means for operators with crypto payment rails, why a missing crypto-asset service provider (CASP) authorisation further down the payment chain is now a licensing problem rather than a technical one, and why regulators are increasingly judging compliance on how it works in practice rather than on what the policy file says.
Key findings
- On MiCA’s reach into iGaming: ‘It does not replace gambling regulation, but it adds another layer of scrutiny.’
- On unauthorised payment partners: ‘Under the post-transition MiCA regime, relying on assurances is no longer enough.’
- On running two regimes at once: ‘We encourage operators to treat them as one integrated compliance framework rather than two separate workstreams.’
- On the most common licensing mistake: ‘My advice is to start with the operating model rather than the licence itself.’
- On what comes next: ‘A licence alone will no longer be enough to stand out.’
What changes for operators with crypto payment rails
European Gaming: MiCA’s transitional period ended on 1 July. For iGaming operators that accept or facilitate crypto payments, what changes immediately, and what is the biggest misconception you are seeing right now?
Mykyta Kim: The immediate change is that crypto payments can no longer be treated as a secondary technical feature sitting outside the main regulatory framework.
If an iGaming operator accepts crypto-assets directly or relies on a payment, custody, exchange or liquidity partner, it now needs to understand whether that partner holds a valid CASP authorisation under MiCA and which specific services that authorisation actually covers.
An iGaming operator does not automatically become a CASP simply because it accepts crypto payments. But its regulatory risk profile changes significantly.
‘Regulators, banks, payment providers and auditors will now look beyond the gambling licence and examine the whole payment chain: who receives the funds, who converts crypto-assets into fiat, who holds the assets, who performs AML checks, and where the customer risk actually sits.’
The biggest misconception I see is the idea that MiCA only concerns crypto exchanges and has nothing to do with iGaming. In practice, that is not true. If crypto infrastructure is embedded into the operator’s business model, especially for deposits, withdrawals, loyalty programmes or high-risk traffic, MiCA becomes part of the broader compliance risk.
It does not replace gambling regulation, but it adds another layer of scrutiny.
When a payment partner has no CASP authorisation
EG: A significant share of formerly registered crypto-asset service providers still do not hold full CASP authorisation. What should an operator do if a payment or liquidity partner it relies on is one of them?
Mykyta Kim: My first piece of advice is not to delay action in the hope that the situation will resolve itself. The MiCA transitional period has now ended, so operators should assume that any key crypto service provider carrying out regulated activities in the EU is expected to comply with the current regulatory framework.
If a payment, exchange, custody or liquidity provider has not obtained CASP authorisation, the operator should immediately carry out both a legal and an operational risk assessment.
It is important to understand exactly which services the provider performs:
- Whether those services fall within MiCA
- Whether the provider is legally entitled to continue operating in the relevant jurisdiction
- Where the provider is also subject to other sector-specific regulatory frameworks such as DORA
- How this may affect payment continuity, banking relationships and the operator’s own compliance obligations.
I would not say that terminating the relationship is always the only correct response. Every case requires an individual legal assessment.
However, if a provider cannot demonstrate its regulatory status, explain the legal basis on which it continues to provide its services or present a clear roadmap going forward, that should be treated as a significant warning sign.
Under the post-transition MiCA regime, relying on assurances is no longer enough.
‘Operators should be able to demonstrate that their entire crypto payment infrastructure complies with the applicable legal requirements.’
Two regimes, one compliance picture
EG: Does CASP authorisation status affect an operator’s own gambling licence standing in any jurisdiction, or do regulators treat the two regimes as fully separate?
Mykyta Kim: From a legal perspective, these are two separate regulatory regimes. Holding or not holding CASP authorisation does not, by itself, determine the status of an operator’s gambling licence. Gambling regulators are not crypto regulators, and MiCA does not regulate gambling activities.
In practice, however, the distinction is becoming less clear-cut.
Where an operator incorporates crypto-assets into its business model, regulators increasingly look beyond the gambling licence itself. They assess whether the payment infrastructure is lawfully structured, whether AML and KYC controls are effective, who provides the underlying services, and whether the operator has an appropriate framework for managing regulatory risk.
‘At Key2Law, we increasingly advise clients who need to address MiCA requirements and gambling licensing in parallel. That is why we encourage operators to treat them as one integrated compliance framework rather than two separate workstreams.’
While the absence of CASP authorisation is not, in itself, a legal ground for losing a gambling licence, reliance on unauthorised service providers or weak oversight of crypto payment flows can attract additional scrutiny from licensing authorities, banking partners and other stakeholders.
In highly regulated markets, the overall quality of governance and risk management is becoming just as important as compliance with individual regulatory requirements.
Where licence applications go wrong
EG: What is the most common structural mistake you see when an operator applies for a gambling licence in a new European market?
Mykyta Kim: The most common mistake is treating licensing as a standalone administrative process. In reality, regulators are not simply reviewing an application package, they are assessing whether the entire business model is capable of operating within a regulated environment.
At Key2Law, we often see operators incorporate a company, sign agreements with suppliers or build their payment infrastructure before addressing fundamental issues such as corporate governance, AML and CDD frameworks, internal controls or the allocation of responsibilities within the group.
By the time these issues are identified during the licensing process, the business structure often has to be redesigned, leading to additional costs, delays and regulatory risk.
‘My advice is to start with the operating model rather than the licence itself.’
- Where will strategic decisions actually be made?
- Who exercises effective control over the business?
- How will payment flows, AML procedures, safeguarding of customer funds and supplier relationships be managed?
When these questions are addressed from the outset, the licensing process is usually more efficient and significantly smoother from a regulatory perspective.
AML files are now tested against practice
EG: How has AML and KYC scrutiny changed for gambling licence applicants over the past year, and what documentation do regulators now expect that they did not a year or two ago?
Mykyta Kim: I would not say that regulators are asking for an entirely new set of AML or KYC documents. The more significant change is that they are examining existing documentation in far greater detail and testing whether it genuinely reflects the operator’s business model.
Submitting a standard set of AML and KYC policies is no longer enough. Regulators expect a risk-based framework tailored to the operator’s activities, including a documented risk assessment, customer due diligence procedures, transaction monitoring processes, suspicious activity reporting mechanisms, internal escalation procedures and clearly defined compliance responsibilities.
They also increasingly request information on the source of funds, group structure, ultimate beneficial ownership and evidence that AML controls are embedded in the company’s day-to-day operations.
Another notable development is the shift from reviewing policies on paper to assessing how they work in practice.
Regulators want to know who is responsible for compliance, what monitoring systems are in place, how staff are trained and how the business responds when risks are identified.
Increasingly, compliance is being assessed as an operational governance framework rather than a collection of internal policies.
No passport for gambling licences
EG: For an operator weighing entry into several EU markets at once, is a single-licence, passport-style approach ever realistic in gambling the way it is under MiCA for crypto, or is fragmentation simply the planning assumption?
Mykyta Kim: The short answer is no.
Unlike MiCA, which provides a framework for offering crypto-asset services across the EU once a CASP has been authorised and the relevant procedures have been completed, there is no equivalent passporting regime for gambling licences. Each Member State sets its own licensing requirements, tax rules, player protection standards and compliance obligations.
‘For that reason, operators should not build their European expansion strategy around the assumption that a single licence will provide access to the entire EU market.’
In practice, that approach often leads to unrealistic timelines, underestimated costs and unnecessary regulatory complications.
I always recommend taking a strategic view from the outset. If an operator plans to enter several markets, it is important to identify priority jurisdictions early and assess differences in local regulation, corporate structuring, technical infrastructure and payment requirements. This makes it possible to build a scalable operating model rather than redesigning the business every time a new market is added.
Although gambling licences cannot be passported, many elements of the compliance framework can be standardised.
Well-designed corporate governance, AML and KYC procedures, internal policies and compliance controls make subsequent licensing processes significantly more efficient, even where separate licences are required in each jurisdiction.
Reading a jurisdiction for the long term
EG: What red flags tell you a jurisdiction is a short-term opportunity rather than a viable long-term base?
Mykyta Kim: In my view, the cost of a licence or the speed of obtaining it should never be the primary factor when choosing a jurisdiction. Decisions based solely on those considerations often result in far greater costs later on.
When we advise clients at Key2Law, the first thing we assess is regulatory predictability.
- How consistent is the regulator’s approach?
- Is there a clear regulatory framework and an established supervisory practice?
- How accessible are banking services, payment infrastructure and local professional support?
It is equally important to understand how the jurisdiction is perceived by banks, investors, B2B partners and other regulators.
‘One of the biggest red flags for me is a jurisdiction that attracts operators with minimal entry requirements but lacks regulatory stability or frequently changes its rules. Those advantages often prove to be short-lived.’
The most successful businesses are rarely built around the cheapest or fastest licence. They are built around jurisdictions that provide long-term regulatory certainty and allow operators to grow without having to constantly restructure their business to keep up with changing regulatory expectations.
The next 12 months: Coordination, not new rules
EG: Which regulatory shift do you expect to cause the most disruption for operators and service providers over the next 12 months?
Mykyta Kim: In my view, the biggest change over the next 12 months will not be a single new regulation but the increasing coordination between regulators and a more holistic approach to assessing regulated businesses.
Companies are no longer being evaluated solely through the lens of one licence or one regulatory framework. Greater attention is being paid to how corporate governance, AML and KYC controls, payment infrastructure, customer protection and risk management work together in practice.
I also expect increased regulatory scrutiny of how crypto-assets are used within regulated industries. Now that the MiCA transitional period has ended, regulators are likely to focus not only on CASPs themselves but also on businesses that rely on crypto infrastructure as part of their operating model.
For operators, this means regularly reviewing service providers, internal controls and the overall compliance framework.
The most resilient businesses are those that treat compliance as a long-term business strategy rather than a regulatory obligation. Those companies are generally better positioned to expand into new markets, build stronger relationships with banks and payment providers, and adapt more efficiently to regulatory change.
I believe that, over the coming years, a licence alone will no longer be enough to stand out.
‘The real competitive advantage will be the ability to demonstrate that a business has a mature, well-governed and sustainable compliance framework that inspires confidence among regulators, partners and customers alike.’
About Key2Law
Key2Law is an international consulting company advising businesses in high-risk and rapidly evolving industries. It specialises in company incorporation, international business structuring, tax, bank account opening, and licensing, with a focus on crypto, iGaming, fintech, and electronic money institutions (EMIs). Mykyta Kim is the company’s chief executive officer.
The post Mykyta Kim, Key2Law, on post-MiCA compliance: ‘A licence alone will no longer be enough to stand out’ appeared first on European Gaming Industry News.

